Description
When deleting a StackSet, purge_stacks set to true also deletes its associated stacks. This can affect resources across accounts and Regions; deleting stacks that should remain may cause outages or data loss.
This module applies purge_stacks to deletion tasks with state set to absent. Setting it to false removes the StackSet but retains the stacks, which are no longer managed by that StackSet. Retention does not replace backups or prevent deletion through other paths.
Potential impact
- Deleting stacks across multiple locations can disrupt services and affect stored data.
- Retained stacks can incur unmanaged costs or lose clear operational ownership.
Remediation
Check the target StackSet and the accounts, Regions and dependencies of all its stacks. Explicitly set purge_stacks: false on the deletion task when the stacks must remain. Review resource deletion policies and backups, then verify retained resources and their ongoing ownership. If complete cleanup is intended, validate that deletion scope first.
Examples
These examples intentionally remove an existing StackSet. Replace my-stack with the actual target and check the execution account and Region. Both delete the StackSet itself; they are not creation tasks.
Before
- name: Remove a StackSet and its stacks
community.aws.cloudformation_stack_set:
name: my-stack
state: absent
purge_stacks: true
This deletes the StackSet and its associated stacks. Resource deletion or retention also depends on each stack’s deletion policies.
After
- name: Remove a StackSet while retaining its stacks
community.aws.cloudformation_stack_set:
name: my-stack
state: absent
purge_stacks: false
This removes the StackSet while retaining its stacks. Verify their state, operational ownership and costs.